VLDB 2026 Research / reviewers in the wild / expert
Ghita Mezzour
dblp:75/6635
· DBLP profile ↗
13ranked-venue papers
2as first author
3since 2021 · last 2023
0000-0002-4306-1589ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 3Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorComputer networks · 2 · 1 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | STRisk: A Socio-Technical Approach to Assess Hacking Breaches RiskabstractData breaches have begun to take on new dimensions and their prediction is becoming of great importance to organizations. Prior work has addressed this issue mainly from a technical perspective and neglected other interfering aspects such as the social media dimension. To fill this gap, we propose STRisk which is a predictive system where we expand the scope of the prediction task by bringing into play the social media dimension. We study over 3800 US organizations including both victim and non-victim organizations. For each organization, we design a profile composed of a variety of externally measured technical indicators and social factors. In addition, to account for unreported incidents, we consider the non-victim sample to be noisy and propose a noise correction approach to correct mislabeled organizations. We then build several machine learning models to predict whether an organization is exposed to experience a hacking breach. By exploiting both technical and social features, we achieve a Area Under Curve (AUC) score exceeding 98%, which is 12% higher than the AUC achieved using only technical features. Furthermore, our feature importance analysis reveals that open ports and expired certificates are the best technical predictors, while spreadability and agreeability are the best social predictors. Hicham Hammouchi, Narjisse Nejjari, Ghita Mezzour, Mounir Ghogho, Houda Benbrahim |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | Detecting the impact of software vulnerability on attacks: A case study of network telescope scans
Abdellah Houmz, Ghita Mezzour, Karim Zkik, Mounir Ghogho, Houda Benbrahim |
J. Netw. Comput. Appl. | 2 |
| 2021 | $\sf {DBank}$DBank: Predictive Behavioral Analysis of Recent Android Banking TrojansabstractUsing a novel dataset of Android banking trojans (ABTs), other Android malware, and goodware, we develop the$\sf {DBank}$system to predict whether a given Android APK is a banking trojan or not. We introduce the novel concept of aTriadic Suspicion Graph(TSG for short) which contains three kinds of nodes: goodware, banking trojans, and API packages. We develop a novel feature space based on two classes of scores derived from TSGs:suspicion scores(SUS) andsuspicion ranks(SR)—the latter yields a family of features that generalize PageRank. While TSG features (based on SUS/SR scores) provide very high predictive accuracy on their own in predicting recent (2016-2017) ABTs, we show that the combination of TSG features with previously studied lightweight static and dynamic features in the literature yields the highest accuracy in distinguishing ABTs from goodware, while preserving the same accuracy of prior feature combinations in distinguishing ABTs from other Android malware. In particular,$\sf {DBank}$’s overall accuracy in predicting whether an APK is a banking trojan or not is up to 99.9% AUC with 0.3% false positive rate. Moreover, we have already reported two unlabeled APKs from VirusTotal (which$\sf {DBank}$has detected as ABTs) to the Google Android Security Team—in one case, we discovered it before any of the 63 anti-virus products on VirusTotal did, and in the other case, we beat 62 of 63 anti-viruses on VirusTotal. This suggests that$\sf {DBank}$is capable of making new discoveries in the wild before other established vendors. We also show that our novel TSG features have some interesting defensive properties as they are robust to knowledge of the training set by an adversary: even if the adversary uses 90% of our training set and uses the exact TSG features that we use, it is difficult for him to infer$\sf {DBank}$’s predictions on APKs. We additionally identify the features that best separate and characterize ABTs from goodware as well as from other Android malware. Finally, we develop a detailed data-driven analysis of five major recent ABT families:FakeToken,Svpeng,Asacub,BankBot, andMarcher, and identify the features that best separate them from goodware and other-malware. Chongyang Bai, Qian Han, Ghita Mezzour, Fabio Pierazzi, V. S. Subrahmanian |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2019 | Analyzing Cybersecurity Job Market Needs in Morocco by Mining Job AdsabstractCybersecurity jobs are becoming more and more in demand for companies and governmental organizations, especially with the increasing number of cyber-threats in the world. In order to keep up with these changes, a study for the cybersecurity job market needs is required in order to help universities adapt their curricula and train more skilled graduates. However, most of prior work focuses on IT jobs and overlooks the cybersecurity field which makes the analysis of the needs of this field ambiguous. In this paper, we collect job ads from 9 Moroccan job portals from February 2017 to June 2018. After removing duplicates, we result in 409 job ads. Then, we split the data into two categories that are cybersecurity jobs and IT jobs that require cybersecurity. We use text analysis techniques to extract skills and requirements listed in these ads. More specifically, we extract the education level, programming languages, natural languages, years of experience, certifications and types of contract listed in these ads. Our paper finds that skills that are highly requested, such as risk analysis methods and certificates are not emphasized in cybersecurity-specific curriculum, while skills that are less in demand, such as a range of programming languages, are taught more regularly in universities. Additionally, more jobs require some understanding of English than of French, which was surprising given prevalence of French in Morocco. Our results can be used to reshape universities training in order to meet the demand of the job market. Ibrahim Rahhal, Ibtissam Makdoun, Ghita Mezzour, Imane Khaouja, Kathleen M. Carley, Ismail Kassou |
EDUCON | 3 |
| 2019 | Predicting Probing Rate Severity by Leveraging Twitter SentimentsabstractProbing is the first step to gain access to a network. Predicting the rate levels of probing against a network sufficiently ahead of time could be insightful to security analysts and practitioners. Indeed, an accurate prediction would help to understand the potential threats and attacks menacing an organization's network. However, this prediction problem is a challenging task; prior works make predictions over time horizons not exceeding a few hours. In this work, we propose a machine learning approach to predict the next day probing rate levels for a network telescope by leveraging Twitter users' sentiments toward the country hosting the network telescope. First, we investigate the relationship between probing rates and Twitter sentiments. Second, we cluster the probing rates to determine the probing severity levels. Finally, we predict future rate levels using several classifiers. We show that incorporating negative sentiments improves significantly the prediction performance. This demonstrates the importance of incorporating social signals as predictors when predicting future probing rates. Hicham Hammouchi, Ghita Mezzour, Mounir Ghogho, Mohammed Elkoutbi |
IWCMC | 2 |
| 2018 | Analyzing the needs of the offshore sector in Morocco by mining job adsabstractThe offshore sector creates a large number of job opportunities in Morocco. Analyzing job ads related to that sector can help universities adapt their curricula in order to produce more employable graduates. Unfortunately, analyzing these ads is challenging because they are mostly non-structured. Most prior work, however, focuses on analyzing structured and semi-structured job ads through keyword search and regular expressions. In this work, we collect and analyze job ads related to the offshore sector in Morocco over the period February-August 2017. We use a variety of machine learning and text mining techniques to process these ads. We examine the natural languages, programming languages, education level, and years of experience needed. We also examine contract type and salary when available. Our results reveal that French is the most needed language in offshore jobs, but that other foreign languages (English and Spanish) are also needed. We also find that the most needed offshore IT jobs are development and web design jobs. The most needed programming languages for these jobs are Java, SQL, JavaScript and PHP. Imane Khaouja, Ibrahim Rahhal, Mehdi Elouali, Ghita Mezzour, Ismail Kassou, Kathleen M. Carley |
EDUCON | 4 |
| 2018 | Analysis of Hacking Related Trade in the DarkwebabstractThe non-referenced web is estimated at five hundred times the size of the surface web. Darkweb represents about 6% of the non-referenced web and includes all kinds of delinquency: drug trafficking, counterfeiting, hacking market etc. Several studies about Darkweb marketplaces have been carried out, focusing mainly on the analysis of drug trafficking or the extraction of products sold in different forums. To the best of our knowledge, by the time of this study, no work has yet been done to analyze hacking trade business.Most hackers rely on malwares and softwares offered in different cyber markets to commit their attacks. The main objective of our work is to present an exploratory analysis of the illegal trade that is developing in this marketplaces in order to have a clear idea of threats that may harm individuals, industries and organizations. Through this work, we have been able to give a clear insight on the hacking market. The main motivation of sellers in this market is profit making, in fact this market generated over 26 million USD during the period studied. Product accessibility is also an alarming factor: 85% of the products offered do not exceed 150 USD, making cyber crime accessible to all. Finally, one cell controls almost the entire market, indicating the presence of a well-organized infrastructure. The results of this analysis are discussed below. Othmane Cherqi, Ghita Mezzour, Mounir Ghogho, Mohammed Elkoutbi |
ISI | 2 |
| 2018 | Exploratory Data Analysis of a Network Telescope Traffic and Prediction of Port Probing RatesabstractUnderstanding the properties exhibited by large scale network probing traffic would improve cyber threat intelligence. In addition, the prediction of probing rates is a key feature for security practitioners in their endeavors for making better operational decisions and for enhancing their defense strategy skills. In this work, we study different aspects of the traffic captured by a /20 network telescope. First, we perform an exploratory data analysis of the collected probing activities. The investigation includes probing rates at the port level, services interesting top network probers and the distribution of probing rates by geolocation. Second, we extract the network probers exploration patterns. We model these behaviors using transition graphs decorated with probabilities of switching from a port to another. Finally, we assess the capacity of Non-stationary Autoregressive and Vector Autoregressive models in predicting port probing rates as a first step towards using more robust models for better forecasting performance. Mehdi Zakroum, Abdellah Houmz, Mounir Ghogho, Ghita Mezzour, Abdelkader Lahmadi, Jérôme François, Mohammed Elkoutbi |
ISI | 4 |
| 2018 | Securing the Internet of Things (IoT)abstractInternet of Things is a large network of interconnected ”things”. IoT refers to the exchange of data and information from real world devices to the Internet. IoT technology will enable breakthrough applications in several areas such as e-Health, smart cities, transportation and industry, and includes multiple technologies, cloud computing, communication, etc. IoT reveals not only the possibilities of high efficiency and low cost, but also scalability. On the other hand, security issues exist and are a major concern for researchers. This article is a systematic literature review (SLR) where show the most basic and common architecture proposed for IoT with a security analysis of each layer. This SLR is also made to present IoT security solutions, as well as a comparison of these solutions. Finally we will present future research directions. Abla El bekkali, Mohammed Boulmalf, Mohammed Essaaidi, Ghita Mezzour |
WINCOM | 4 |
| 2018 | A Socio-Computational Approach to Predicting Bioweapon ProliferationabstractPredicting countries that will seek bioweapons (BW) enables the international community to act early in order to prevent these countries from acquiring such weapons. Unfortunately, the literature on countries' BW programs mainly consists of case studies that focus on one or a few countries. Although case studies are valuable, they are typically not predictive. Moreover, case studies require substantial effort and expertise, and are thus unfeasible for all countries. In this paper, we develop a computational methodology that predicts countries that will seek BW. Our methodology consists of a sociocultural model and indicators that computationally capture expert opinions about why and how countries acquire BW. Our methodology systematically examines all countries in the world and can be used by non-BW experts based on publicly available data. We validate our methodology by examining the methodology's ability to predict historical BW proliferators. Ghita Mezzour, William Frankenstein, Kathleen M. Carley, L. Richard Carley |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2009 | A Trustable Reputation Scheme Based on Private RelationshipsabstractOnline reviews are widely used for purchase decisions. Their trustworthiness is limited, however, by fake reviews. Fortunately, opinions from friends in a social network are more reliable but less convenient to obtain. Combining the advantages purchase decisions of online reviews and opinions from friends can be achieved by enabling users to recognize the online reviews originating from their friends. By leveraging buyerspsila trust to nearby friends within their social network, it is possible to provide them in some cases with online reviews they can entirely trust. In this paper we present techniques to enable users to recognize the online reviews from their friends in a privacy-preserving manner. Our approach has many applications such as Internet auctions and online gaming. Shih-Ying Chang, Ghita Mezzour, Adrian Perrig |
ASONAM | 3 |
| 2009 | Privacy-Preserving Relationship Path Discovery in Social Networks
Ghita Mezzour, Adrian Perrig, Virgil D. Gligor, Panagiotis Papadimitratos |
CANS | 1 |
| 2007 | MiniSec: a secure sensor network communication architectureabstractSecure sensor network communication protocols need to provide three basic properties: data secrecy, authentication, and replay protection. Secure sensor network link layer protocols such as Tiny-Sec [10] and ZigBee [24] enjoy significant attention in the community. However, TinySec achieves low energy consumption by reducing the level of security provided. In contrast, ZigBee enjoys high security, but suffers from high energy consumption. Mark Luk, Ghita Mezzour, Adrian Perrig, Virgil D. Gligor |
IPSN | 2 |